Clickjacking prevention
Abstract
Systems and methods provide for clickjacking prevention code provided in an embedded webpage to prevent clickjacking when the embedded webpage is called by an embedding webpage determined to be illegitimate. When the embedded webpage is loaded on a user device, the clickjacking prevention code is executed and initially prevents content of the embedded webpage from being rendered. Additionally, the clickjacking prevention code sends a message containing a secret to a known domain that provides legitimate embedding webpages. When the embedding webpage sends a message to the embedded webpage, the message is checked to see if it contains the secret. If the message contains the secret, the embedding webpage is legitimate since it originated from the known domain, and the content of the embedded webpage is rendered. Alternatively, if the message does not contain the secret, the content of the webpage is not rendered.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1. One or more non-transitory computer storage media storing computer-useable instructions that, when executed by a computing device, cause the computing device to perform operations, the operations comprising:
preventing content of an embedded webpage from being rendered on a user device, the embedded webpage having been called by an embedding webpage;
sending a message containing a secret from the embedding webpage on the user device to a server of a known domain;
after sending the message containing the secret to the server, receiving a message from the embedding webpage that called the embedded webpage;
determining, on the user device, whether the message from the embedding webpage includes the secret, the message from the embedding webpage including the secret when the embedding webpage is legitimate and receives the secret from the server after the secret is sent to the server from the user device;
when the message from the embedding webpage includes the secret, allowing the content of the embedded webpage to be rendered; and
when the message from the embedding webpage does not include the secret, continuing to prevent the content of the embedded webpage from being rendered.
2. The one or more computer storage media of claim 1 , wherein the content of the embedded webpage is prevented from being rendered using a framekiller technique.
3. The one or more computer storage media of claim 1 , wherein the message to the known domain is a PostMessage.
4. The one or more computer storage media of claim 1 , wherein the message from the embedding webpage is a PostMessage.
5. The one or more computer storage media of claim 1 , wherein the embedding webpage calls the embedded webpage to be displayed within an iframe.
6. The one or more computer storage media of claim 1 , wherein the operations are performed by a web browser on the user device.
7. The one or more computer storage media of claim 1 , wherein the operations further comprise sending a message containing the secret to at least one other known domain.
8. A computer-implemented method for preventing clickjacking on a user device, the method comprising:
receiving an embedded webpage called by an embedding webpage rendered on the user device, the embedded webpage containing clickjacking prevention code; and
executing the clickjacking prevention code on the user device to perform operations that include:
preventing content of the embedded webpage from being rendered;
sending a message containing a secret to a server of a known domain;
after sending the message containing the secret to the server, receiving a message from the embedding webpage that called the embedded webpage;
determining whether the message from the embedding webpage includes the secret, the message from the embedding webpage including the secret when the embedding webpage is legitimate and receives the secret from the server after the secret is sent to the server from the user device;
when the message from the embedding webpage includes the secret, allowing the content of the embedded webpage to be rendered; and
when the message from the embedding webpage does not include the secret, continuing to prevent the content of the embedded webpage from being rendered.
9. The method of claim 8 , wherein the content of the embedded webpage is prevented from being rendered using a framekiller technique.
10. The method of claim 8 , wherein the message to the known domain is a PostMessage.
11. The method of claim 8 , wherein the message from the embedding webpage is a PostMessage.
12. The method of claim 8 , wherein the embedding webpage calls the embedded webpage to be displayed within an iframe.
13. The method of claim 8 , wherein the method is performed by a web browser on the user device.
14. The method of claim 8 , wherein the method further comprises sending a message containing the secret to at least one other known domain.
15. A computer system comprising:
one or more hardware processors; and
one or more computer storage media storing computer-useable instructions that, when used by the one or more processors, cause the one or more processors to:
receive a request for an embedded webpage from a user device, the request having been generated in response to an embedding webpage calling the embedded webpage; and
providing the embedded webpage in response to the request, the embedded webpage including clickjacking prevention code that when executed on the client device causes the client device to perform operations that include:
preventing content of the embedded webpage from being rendered;
sending a message containing a secret to a server of a known domain;
after sending the message containing the secret to the server, receiving a message from the embedding webpage that called the embedded webpage;
determining whether the message from the embedding webpage includes the secret, the message from the embedding webpage including the secret when the embedding webpage is legitimate and receives the secret from the server after the secret is sent to the server from the user device;
when the message from the embedding webpage includes the secret, allowing the content of the embedded webpage to be rendered; and
when the message from the embedding webpage does not include the secret, continuing to prevent the content of the embedded webpage from being rendered.
16. The system of claim 15 , wherein the content of the embedded webpage is prevented from being rendered using a framekiller technique.
17. The system of claim 15 , wherein the message to the known domain is a PostMessage.
18. The system of claim 15 , wherein the message from the embedding webpage is a PostMessage.
19. The system of claim 15 , wherein the embedding webpage calls the embedded webpage to be displayed within an iframe.
20. The system of claim 15 , wherein the operations further comprise sending a message containing the secret to at least one other known domain.Join the waitlist — get patent alerts
Track US10320808B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.